A security issue was discovered in Kubernetes where under certain conditions, an unauthenticated attacker with access to the pod network can achieve arbitrary code execution in the context of the ingress-nginx controller. This can lead to disclosure of Secrets accessible to the controller. (Note that in the default installation, the controller can access all Secrets cluster-wide.)
PoC: IngressNightmare-POCs
CVE-2025-1974
PoC: nginxnightmare
IngressNightmare-POC CVE-2025-1974 https://www.wiz.io/blog/ingress-nginx-kubernetes-vulnerabilities#how-did-we-discover-ingressnightmare-24
PoC: CVE-2025-1974
Poc for Ingress RCE
PoC: IngressNightterror
My view on IngressNightmare vulnerability (CVE-2025-1974)
PoC: CVE-2025-1974
ingress-nginx admission controller RCE escalation PoC
PoC: CVE-2025-1974-PoC-exploit
Kubernetes Ingress-nginx RCE (IngressNightmare)
PoC: Blackash-CVE-2025-1974
CVE-2025-1974
PoC: CVE-2025-1974
WHS3기 가상화 취약한(CVE) Docker 환경 구성 과제
PoC: CVE-2025-1974-go
Exploit CVE-2025-1974 with a single file.
PoC: CVE-2025-1974
CVE-2025-1974 PoC 코드
PoC: POC-IngressNightmare-CVE-2025-1974
POC IngressNightmare (CVE-2025-1974), modified from https://github.com/yoshino-s/CVE-2025-1974
PoC: ingress-nightmare
IngressNightmare (CVE-2025-1974)
PoC: CVE-2025-1974
A minimal test tool to help detect annotation injection vulnerabilities in Kubernetes NGINX Ingress controllers. This script sends a crafted AdmissionReview request to simulate a potential exploit path from CVE-2025-1974 and checks for signs of misinterpreted annotations in controller logs.
PoC: CVE-2025-1974-poc
PoC of CVE-2025-1974, modified from the world-first PoC~
PoC: ingressnightmare-detection-poc
Proof-of-Concept Tool to detect IngressNightmare (CVE-2025-1974) via (non-intrusive) active means.
PoC: IngressNightmare-RCE-POC
PoC for CVE-2025-1974: Critical RCE in Ingress-NGINX (<v1.12.1) via unsafe config injection. Exploitable from the pod network without credentials, enabling code execution and potential cluster takeover. Fixed in v1.12.1 and v1.11.5. For research/education only.
PoC: IngressNightmare-CVE-2025-1974
Exploit for CVE-2025-1974
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Get alerted for CVEs like this
Register your stack and get notified within minutes when a matching CVE drops.
Start monitoring free